Описание
Unspecified vulnerability in certain COM objects in Microsoft Office Web Components 2000 allows user-assisted remote attackers to execute arbitrary code via vectors related to DataSource that trigger memory corruption, aka "Office Web Components DataSource Vulnerability."
Ссылки
- Vendor Advisory
- Patch
- US Government Resource
- Vendor Advisory
- Patch
- US Government Resource
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:microsoft:biztalk_server:2000:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:biztalk_server:2002:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:commerce_server:2000:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_security_and_acceleration_server:2000:sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*
cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_.net:2002:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_.net:2003:sp1:*:*:*:*:*:*
EPSS
Процентиль: 98%
0.45718
Средний
9.3 Critical
CVSS2
Дефекты
CWE-94
Связанные уязвимости
github
почти 4 года назад
Unspecified vulnerability in certain COM objects in Microsoft Office Web Components 2000 allows user-assisted remote attackers to execute arbitrary code via vectors related to DataSource that trigger memory corruption, aka "Office Web Components DataSource Vulnerability."
EPSS
Процентиль: 98%
0.45718
Средний
9.3 Critical
CVSS2
Дефекты
CWE-94